Author : MD TAREQ HASSAN | Updated : 2022/02/07

Prerequisites

Resource Provider

Microsoft Sentinel - enable Microsoft.SecurityInsights resource provider

Log Analytics Workspace

Add Sentinel to Workspace Using Azure Portal

Add Sentinel to Workspace Using Azure Portal

Plan Data Sources

After adding Sentinel to Log Analytics Workspace, we should plan from which resources/services data will be ingested into sentinel.

Azure Activity

Azure AD (for simplicity, only 2 types of logs are being considered)

Azure Firewall

Application Gateway WAF

The above is just example, you can choose many data sources if required.

Connect Data Sources

Details of connecting data sources to sentinel are described below.

Connect Azure Activity

Connect Azure AD

Connect Azure Firewall

Connect Application Gateway WAF